Claude Docs Consultant
centminmod/my-claude-code-setup
Consult official Claude Code documentation from code.claude.com using selective fetching.
Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.
$ npx skills add BankrBot/skills --skill polygraph -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BankrBot/skills polygraph --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/polygraph .claude/skills/polygraph && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .claude/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BankrBot/skills/tree/main/polygraphType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BankrBot/skills --skill polygraph -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BankrBot/skills polygraph --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/polygraph .agents/skills/polygraph && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .agents/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BankrBot/skills --skill polygraph -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BankrBot/skills polygraph --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/polygraph .cursor/skills/polygraph && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .cursor/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BankrBot/skills.git --path polygraph--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BankrBot/skills --skill polygraph -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BankrBot/skills polygraph --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/polygraph .gemini/skills/polygraph && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .gemini/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BankrBot/skills polygraphInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BankrBot/skills --skill polygraph -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/polygraph .github/skills/polygraph && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .github/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BankrBot/skills --skill polygraph -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BankrBot/skills polygraph --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/polygraph .opencode/skills/polygraph && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "polygraph" agent skill from https://github.com/BankrBot/skills/tree/main/polygraph into .opencode/skills/polygraph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polygraph", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
polygraphBehavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.
Polygraph is an agent skill from BankrBot/skills. Behavioral trust grades (A–F) for MCP servers. Use when an agent needs to check whether an MCP server is safe before using it, verify an onchain attestation before trusting or paying a server, look up a server's published grade, get a project graded, or understand why a server received a grade. Polygraph connects to an MCP server the way an agent would, fingerprints its exact tool surface, and runs behavioral probes — prompt-injection (C-01), permission/egress overreach (C-02), sensitive-data leak (C-03), and…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `catalog.json`, `references/bankr-integration.md` and `references/ci-gate.md`).
It sits in Agent Workflows, covering Prompt injection and agent security, MCP servers and CI/CD. It works with Model Context Protocol. The repository describes itself as: Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit dc47eed. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
polygraph.sonpmjs.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Polygraph loads about 3.4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,531 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 1,531 words (~3,371 tokens).
“Agents wire up third-party MCP servers and then trust whatever those servers' tools return. Polygraph tests an MCP server's behavior before your agent does, and assigns a letter grade A–F backed by reproducible evidence.”
SKILL.md and 6 other files (references) in polygraph of BankrBot/skills.
Open the folder on GitHubat commit dc47eed
Polygraph next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Polygraph this skillBankrBot/skills | 1.2k | — | ~3.4k | Automated safety check: Pass | None | |
| Claude Docs Consultantcentminmod/my-claude-code-setup | 2.7k | — | ~959 | Automated safety check: Pass | MIT | |
| Automated Triagesickn33/agentic-awesome-skills | 47k | 1 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Skill Security Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | CC0-1.0 | |
| Forensifyalexgreensh/repo-forensics | 187 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Reins Runtime Securitypegasi-ai/reins | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 |
centminmod/my-claude-code-setup
Consult official Claude Code documentation from code.claude.com using selective fetching.
sickn33/agentic-awesome-skills
Triage Monte Carlo alerts interactively or build an automated workflow.
sickn33/agentic-awesome-skills
Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
pegasi-ai/reins
Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.
iflytek/skillhub
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
BankrBot/skills
Builds onchain apps with Coinbase's OnchainKit React components and TypeScript utilities: wallet connection, identity, token swaps, transactions and checkout flows.
BankrBot/skills
Lists AgenticBets prediction markets on Base, shows odds, places UP or DOWN bets on token prices in USDC and claims winnings through the Bankr wallet API.
BankrBot/skills
Creates AI2Human tasks for steps that need a real person, such as manual QA or local checks, and returns a task URL the agent can track.
BankrBot/skills
Lets an agent inspect and operate AZZLE V2 tasks on Base through Bankr, from posting and claiming to funding, delivery, release and disputes, behind verified deployment pins.
BankrBot/skills
Inspect B20 token contract addresses on Base through B20 Console.
BankrBot/skills
Donate to charities onchain via Endaoment. An agent skill from BankrBot/skills.
Works with
Categories
Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. Polygraph is an agent skill from BankrBot/skills. Behavioral trust grades (A–F) for MCP servers.
Polygraph fits situations like: an agent needs to check whether an MCP server is safe before using it; verify an onchain attestation before trusting; paying a server; look up a servers published grade.
Run `npx skills add BankrBot/skills --skill polygraph -a claude-code`. Or copy the skill folder (polygraph in BankrBot/skills) into .claude/skills/polygraph in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BankrBot/skills --skill polygraph -a codex`. Or copy the skill folder (polygraph in BankrBot/skills) into .agents/skills/polygraph in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BankrBot/skills --skill polygraph -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/polygraph, .gemini/skills/polygraph, .github/skills/polygraph and .opencode/skills/polygraph in your project.
Going by SKILL.md and its folder, Polygraph needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js; Docker.
SKILL.md names 2 domains. As links in the text: polygraph.so and npmjs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
No licence was found for Polygraph or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Polygraph: Claude Docs Consultant (centminmod/my-claude-code-setup, 2.7k stars), Automated Triage (sickn33/agentic-awesome-skills, 47k stars), Skill Security Audit (sickn33/agentic-awesome-skills, 47k stars) and Forensify (alexgreensh/repo-forensics, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BankrBot (a GitHub organization) maintains it in BankrBot/skills, which has 1,201 GitHub stars. The repository holds 104 skills in this directory. The repository was last updated on October 5, 2026.
Source: BankrBot/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.